This release appears healthy and suitable for dependency use: it has a strong release cadence with 81 releases in roughly 12 months, is a stable non-prerelease version, is not deprecated, is actively pushed, and is backed by an organization-owned repository with repository tests and a clear MIT license. The main concerns are limited contributor breadth, with 95.7% of recent commits from one contributor, and the absence of a security policy or security-scanning tooling. Low repository popularity and the missing packaged README/changelog are weaker concerns because the package is actively released, the repository contains tests, and the package artifact has a focused source tree.
82%
Total Score
88
100
94
90
One contributor made 45 of 47 recent commits, creating a concentrated bus factor and a real continuity concern. The second contributor remains active and the repository is organization-owned, which partly mitigates this risk.
Composer build tooling is present, but no security-scanning tools were detected; the missing security automation is a transparency and assurance gap, though not evidence of unfitness on its own.
The repository has no security policy, reducing transparency about vulnerability reporting and response procedures.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/process Version ^7.3|^8.0 | — | — |
tempest/support Version 3.19.2 | — | — |
tempest/datetime Version 3.19.2 | — | — |
tempest/container Version 3.19.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.